NEAR Intents says the roughly $3.8 million stolen in its Oct. 1 exploit has been returned in full, days after the suspected attacker began messaging the protocol on-chain and asked for Signal contact details. The incident had briefly frozen deposits and withdrawals across 11 blockchains.
Near Intents exploit traced to cross-chain infrastructure
The incident began on October 1, when Near Intents halted services after detecting a vulnerability involving the interaction between its Omni deposit and withdrawal infrastructure and an Intents smart contract.
According to the available report, the flaw was located on the smart-contract side and was patched after detection. The resulting emergency response temporarily affected deposits and withdrawals across 11 networks, including BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar and Scroll.
The scope of the disruption reflects the architecture of Near Intents, which is designed to coordinate transactions across different blockchain environments.
Its official documentation describes the platform as infrastructure for cross-chain swaps, liquidity access and transaction execution without requiring users to manually manage individual bridges.
The incident therefore became more than a single-chain security event. It involved infrastructure linking smart contracts, wallets, cross-chain mechanisms and external blockchain networks.
Near Intents funds moved through BNB Chain
Initial analysis indicated that the suspicious activity was associated with infrastructure connected to the HOT Bridge treasury on BNB Chain rather than a direct compromise of the underlying NEAR blockchain.
Blockchain investigator ZachXBT identified unusual outflows from a BNB Chain hot wallet associated with Near Intents.
The assets were subsequently moved through KuCoin and bridged into Bitcoin, according to the reporting. The available evidence did not establish that the NEAR base chain itself had been compromised.
During the recovery process, the address involved in moving the funds began communicating through on-chain transactions. It transferred 0.295 ETH on Ethereum and later sent 1 BNB to a recovery wallet.
Those transactions included a message asking for Signal contact details, suggesting that communication had begun between the parties involved in the incident.
The movement of the stolen assets across several networks is significant because it demonstrates how quickly funds can move between blockchain ecosystems following a security breach.
Near Intents sets recovery deadline for suspected attacker
As investigators worked to trace the funds, Near Intents general manager Alex Shevchenko publicly released recovery addresses for Bitcoin, BNB Chain and Solana. The addresses were accompanied by a 48-hour deadline directed at the suspected attacker.
The original report noted that the suspected attacker had not been publicly identified by name and that evidence supporting the identification claim had not been disclosed publicly.
The recovery subsequently changed the situation considerably. The approximately $3.8 million in assets was reported as returned in full, removing the immediate financial loss associated with the exploit.
The protocol had already said it would cover affected users, meaning the recovery was separate from its stated reimbursement commitment.
What Near Intents recovery means for investors
The recovery of the funds provides an important financial development, but it does not resolve every issue raised by the exploit.
The next stage is likely to focus on understanding how the vulnerable interaction between its Omni infrastructure and smart contract enabled the unauthorized withdrawals in the first place.
The available report says a more detailed post-mortem was expected, while the incident had also been reported to law enforcement and security and blockchain analytics firms were involved in tracing the assets.
A successful recovery limits the immediate financial consequences, while a technical post-mortem can provide information about the vulnerability, the affected infrastructure and the safeguards introduced after the incident.
The episode also puts renewed attention on the risks associated with cross-chain infrastructure. Near Intents currently promotes its ability to connect assets and liquidity across multiple blockchain networks, with its official platform reporting activity spanning dozens of chains.
The recovery reduces the immediate financial damage from the exploit, but investors will still have to assess subsequent disclosures about the vulnerability, security upgrades and the protocol’s broader risk-management measures.
Until that information is fully documented, the Near Intents incident remains both a recovery story and a reminder that cross-chain convenience can introduce complex security dependencies.
The return of the funds addresses the immediate loss; understanding the failure that enabled the exploit will be central to evaluating what happens next.